Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Local Traffic Manager CRITICAL 9.8
CVE-2018-5506

In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_mod and mod_auth_f5_auth_token.cpp allow po…

Fix: after 12.1.3.1
Fix from $2,300 2018-04-13
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6148

Responses to SOCKS proxy requests made through F5 BIG-IP version 13.0.0, 12.0.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5 may cause a disruption of s…

Fix: after 12.1.3
Fix from $1,950 2018-04-13
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6155

On F5 BIG-IP 13.0.0, 12.0.0-12.1.3.1, 11.6.0-11.6.2, 11.4.1-11.5.5, or 11.2.1, malformed SPDY or HTTP/2 requests may result in a disruption of servic…

Fix: after 12.1.3
Fix from $1,950 2018-04-13
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5507

On F5 BIG-IP versions 13.0.0, 12.1.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5, vCMP guests running on VIPRION 2100, 4200 and 4300 series blades cann…

Fix: after 12.1.3
Fix from $1,950 2018-04-13
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5510

On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence of packets on IPv6 virtual s…

Mitigation only
Fix from $1,950 2018-04-13
Big Ip Local Traffic Manager HIGH 7.2
CVE-2018-5511EPSS 15%

On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), als…

No fix yet
Fix from $1,950 2018-04-13
Big Ip Local Traffic Manager MEDIUM 6.5
CVE-2017-6158

In F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 there is a vulnerability in TMM related to handling of invalid IP addresses.

Fix: after 12.1.2
Fix from $1,600 2018-04-13
Big Ip Local Traffic Manager MEDIUM 6.4
CVE-2017-6156

When the F5 BIG-IP 12.1.0-12.1.1, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 system is configured with a wildcard IPSec tunnel endpoint, it may allow a …

Fix: after 12.1.1
Fix from $1,600 2018-04-13
Big Ip Policy Enforcement Manager MEDIUM 5.9
CVE-2018-5508

On F5 BIG-IP PEM versions 13.0.0, 12.0.0-12.1.3.1, 11.6.0-11.6.2, 11.5.1-11.5.5, or 11.2.1, under certain conditions, TMM may crash when processing c…

Fix: after 12.1.3
Fix from $1,600 2018-04-13
Big Ip Advanced Firewall Manager MEDIUM 5.4
CVE-2017-6143

X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the …

Fix: after 12.1.2
Fix from $1,600 2018-04-13
Big Ip Application Security Manager HIGH 7.5
CVE-2016-7472

F5 BIG-IP ASM version 12.1.0 - 12.1.1 may allow remote attackers to cause a denial of service (DoS) via a crafted HTTP request.

Mitigation only
Fix from $1,950 2018-04-03
Big Ip Access Policy Manager HIGH 8.1
CVE-2018-5504

In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allow…

Fix: 12.1.3.2 / 13.1.0.4+
Fix from $1,950 2018-03-22
Big Ip Access Policy Manager HIGH 7.5
CVE-2018-5502

On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. …

Fix: 13.1.0.4+
Fix from $1,950 2018-03-22
Big Ip Policy Enforcement Manager HIGH 7.5
CVE-2018-5503

On F5 BIG-IP versions 13.0.0 - 13.1.0.3 or 12.0.0 - 12.1.3.1, TMM may restart when processing a specifically crafted page through a virtual server wi…

Fix: 12.1.3.2 / 13.1.0.4+
Fix from $1,950 2018-03-22
Big Ip Access Policy Manager HIGH 7.5
CVE-2018-5509

On F5 BIG-IP versions 13.0.0 or 12.1.0 - 12.1.3.1, when a specifically configured virtual server receives traffic of an undisclosed nature, TMM will …

Fix: 12.1.3.2 / 12.3.1.2+
Fix from $1,950 2018-03-22
Big Ip Analytics MEDIUM 5.9
CVE-2018-5505

On F5 BIG-IP versions 13.1.0 - 13.1.0.3, when ASM and AVR are both provisioned, TMM may restart while processing DNS requests when the virtual server…

Fix: 13.1.0.4+
Fix from $1,600 2018-03-22
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2014-4024

SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 1…

Fix: after 11.5.1
Fix from $1,600 2018-03-19
Big Iq Centralized Management MEDIUM 6.7
CVE-2017-6152

A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on th…

Fix: after 5.2.0
Fix from $1,600 2018-03-08
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6150

Under certain conditions for F5 BIG-IP systems 13.0.0 or 12.1.0 - 12.1.3.1, using FastL4 profiles, when the Reassemble IP Fragments option is disable…

Fix: after 12.1.3.1
Fix from $1,950 2018-03-01
Big Ip Application Security Manager HIGH 7.5
CVE-2017-6154

On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, the BIG-IP ASM bd daemon may core dump memory under some circumstances wh…

Fix: after 12.1.3.1
Fix from $1,950 2018-03-01
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2018-5500

On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection established leaks a small amount o…

Fix: after 12.1.3.1
Fix from $1,600 2018-03-01
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2018-5501

In some circumstances, on F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, any 11.6.x or 11.5.x release, or 11.2.1, TCP DNS profile allows excess…

Fix: after 12.1.3
Fix from $1,600 2018-03-01
Big Ip Policy Enforcement Manager MEDIUM 6.8
CVE-2017-6169

In versions 13.0.0, 12.0.0-12.1.3, or 11.6.0-11.6.2, an F5 BIG-IP virtual server using the URL categorization feature may cause the Traffic Managemen…

Mitigation only
Fix from $1,600 2018-02-06
Big Ip Local Traffic Manager HIGH 8.1
CVE-2017-6164

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator and WebSafe software version 13.0.0, 12…

Fix: after 12.1.2
Fix from $1,950 2017-12-21
Big Ip Access Policy Manager HIGH 7.6
CVE-2017-0301

In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 and 12.1.2 BIG-IP APM portal access…

Mitigation only
Fix from $1,950 2017-12-21
Big Ip Access Policy Manager HIGH 7.5
CVE-2017-6129

In F5 BIG-IP APM software version 13.0.0 and 12.1.2, in some circumstances, APM tunneled VPN flows can cause a VPN/PPP connflow to be prematurely fre…

Mitigation only
Fix from $1,950 2017-12-21
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6132

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2, 11.6.0 to 11.6…

Fix: after 12.1.2
Fix from $1,950 2017-12-21
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6133

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, undisclosed HTTP …

Fix: after 12.1.2
Fix from $1,950 2017-12-21
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6135

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0, a slow memory leak as a result o…

Mitigation only
Fix from $1,950 2017-12-21
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6138

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, malicious re…

Fix: after 12.1.2
Fix from $1,950 2017-12-21